nerdexam
PECB

ISO-IEC-27001-LEAD-AUDITOR · Question #54

You are performing an ISMS audit at a nursing home where residents always wear an electronic wristband for monitoring their location, heartbeat, and blood pressure. The wristband automatically…

The correct answer is C. Review the internal audit report to make sure the IT department has been audited E. Sampling some mobile devices from on-duty medical staff and validate the mobile device F. Review the asset register to make sure all company's mobile devices are registered. According to ISO/IEC 27001:2022, which specifies the requirements for establishing, implementing, maintaining and continually improving an information security management system (ISMS), clause 5.2 requires top management to establish an information security policy that provides…

Conducting an ISO/IEC 27001 Audit

Question

You are performing an ISMS audit at a nursing home where residents always wear an electronic wristband for monitoring their location, heartbeat, and blood pressure. The wristband automatically uploads this data to a cloud server for healthcare monitoring and analysis by staff. You now wish to verify that the information security policy and objectives have been established by top management. You are sampling the mobile device policy and identify a security objective of this policy is "to ensure the security of teleworking and use of mobile devices" The policy states the following controls will be applied in order to achieve this. Personal mobile devices are prohibited from connecting to the nursing home network, processing, and storing residents' data. The company's mobile devices within the ISMS scope shall be registered in the asset register. The company's mobile devices shall implement or enable physical protection, i.e., pin-code protected screen lock/unlock, facial or fingerprint to unlock the device. The company's mobile devices shall have a regular backup. To verify that the mobile device policy and objectives are implemented and effective, select three options for your audit trail.

Options

  • AInterview the reception personnel to make sure all visitor and employee bags are checked before
  • BReview visitors' register book to make sure no visitor can have their personal mobile phone in the
  • CReview the internal audit report to make sure the IT department has been audited
  • DReview the asset register to make sure all personal mobile devices are registered
  • ESampling some mobile devices from on-duty medical staff and validate the mobile device
  • FReview the asset register to make sure all company's mobile devices are registered
  • GInterview the supplier of the devices to make sure they are aware of the ISMS policy
  • HInterview top management to verify their involvement in establishing the information security

How the community answered

(38 responses)
  • B
    5% (2)
  • C
    63% (24)
  • D
    3% (1)
  • G
    21% (8)
  • H
    8% (3)

Explanation

According to ISO/IEC 27001:2022, which specifies the requirements for establishing, implementing, maintaining and continually improving an information security management system (ISMS), clause 5.2 requires top management to establish an information security policy that provides the framework for setting information security objectives1. Clause 6.2 requires top management to ensure that the information security objectives are established at relevant functions and levels1. Therefore, when verifying that the information security policy and objectives have been established by top management, an ISMS auditor should review relevant documents and records that demonstrate top management's involvement and commitment. To verify that the mobile device policy and objectives are implemented and effective, an ISMS auditor should review relevant documents and records that demonstrate how the policy and objectives are communicated, monitored, measured, analyzed, and evaluated. The auditor should also sample and verify the implementation of the controls that are stated in the policy. Three options for the audit trail that are relevant to verifying the mobile device policy and objectives are: Review the internal audit report to make sure the IT department has been audited: This option is relevant because it can provide evidence of how the IT department, which is responsible for managing the mobile devices and their security, has been evaluated for its conformity and effectiveness in implementing the mobile device policy and objectives. The internal audit report can also reveal any nonconformities, corrective actions, or opportunities for improvement related to the mobile device policy and objectives. Sampling some mobile devices from on-duty medical staff and validate the mobile device information with the asset register: This option is relevant because it can provide evidence of how the mobile devices that are used by the medical staff, who are involved in processing and storing residents' data, are registered in the asset register and have physical protection enabled. This can verify the implementation and effectiveness of two of the controls that are stated in the mobile Review the asset register to make sure all company's mobile devices are registered: This option is relevant because it can provide evidence of how the company's mobile devices that are within the ISMS scope are identified and accounted for. This can verify the implementation and effectiveness of one of the controls that are stated in the mobile device policy.

Topics

#mobile device policy#information security objectives#audit evidence sampling#teleworking controls

Community Discussion

No community discussion yet for this question.

Full ISO-IEC-27001-LEAD-AUDITOR Practice